IP Library Granted Patent US 10,382,454
Granted Patent B2
US 10,382,454 · App. 14/498,266 · Granted Aug 13, 2019

Data mining algorithms adopted for trusted execution environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,382,454
App. No.
14/498,266
Granted
Aug 13, 2019
Kind
B2
Abstract

Distributed systems for protecting networked computer assets from compromise are disclosed. The distributed system includes one or more enterprise event sources, such as endpoint(s). The system also includes a server, such as a Big Data Analytics server, and optionally a security management server such as a Security Information and Event Management server. The Big Data Analytics server processes data collected from the enterprise event sources and produces behavioral profile models for each endpoint (or group of similar endpoints). The profiles, models, and ontology analysis are provided to the endpoints. Endpoint analytics use the output from the analytics servers to detect deviations from the endpoint's behavioral profile.

Claims (42)

1. A storage disk or storage device comprising instructions that, when executed, cause one or more servers to:

create executable instructions associated with endpoint rules and an endpoint ontology model, the endpoint rules to extract events from process behaviors of a plurality of endpoints, the executable instructions to cause a first endpoint to:

generate a first event sequence by arranging first events extracted from first process behaviors performed by the first endpoint into the first event sequence, the first events extracted based on the endpoint rules, at least one of the first events corresponding to a call to an operating system;

generate a third event sequence to determine a correlation fit by attempting to correlate the first event sequence to stored second event sequences of the endpoint ontology model by applying a hidden Markov model to the first event sequence and the second event sequences of the endpoint ontology model, the second event sequences corresponding to known attack patterns, the third event sequence including second events, one or more of the second events being different from one or more of the first events; and

generate a first security alert when the correlation fit satisfies a threshold;

update the endpoint ontology model based on security event data associated with security alerts associated with respective ones of the plurality of endpoints, the security alerts including the first security alert; and

transmit the updated endpoint ontology model to the plurality of endpoints to identify a future attack at one or more of the plurality of endpoints.

2. The storage disk or storage device of claim 1 , wherein the instructions, when executed, cause the one or more servers to transmit the updated endpoint ontology model to trusted execution environments within respective ones of the plurality of endpoints.

3. The storage disk or storage device of claim 1 , wherein the executable instructions are associated with an endpoint behavioral profile including at least one of one or more setup parameters, one or more configurations, or one or more expected behaviors associated with the first endpoint.

4. The storage disk or storage device of claim 1 , wherein the security event data corresponds to a dynamically obtained event or a statically-extracted feature.

5. The storage disk or storage device of claim 4 , wherein the dynamically obtained event is the call to the operating system.

6. The storage disk or storage device of claim 4 , wherein the statically-extracted feature is an indication that the call to the operating system was found in a decompiled application.

7. The storage disk or storage device of claim 1 , wherein the endpoint ontology model includes at least one of an identity, a relationship graph, or an activity.

8. The storage disk or storage device of claim 1 , wherein the endpoint ontology model includes an ontology of a compromised endpoint.

9. The storage disk or storage device of claim 8 , wherein the security event data indicates a correlation of a behavior of the first endpoint with the ontology of the compromised endpoint.

10. A storage disk or storage device comprising instructions that, when executed, cause an endpoint to at least:

extract first events from process behaviors performed by the endpoint using endpoint rules from one or more servers, at least one of the first events corresponding to a call to an operating system of the endpoint;

generate a first event sequence by arranging two or more of the first events into the first event sequence;

generate a third event sequence to determine a correlation fit by attempting to correlate the first event sequence to stored second event sequences of an endpoint ontology model from the one or more servers by applying a hidden Markov model to the first event sequence and the second event sequences of the endpoint ontology model, the second event sequences corresponding to known attack patterns, the third event sequence including second events, one or more of the second events being different from one or more of the first events;

generate a security alert when the correlation fit satisfies a threshold; and

transmit security event data associated with the security alert to the one or more servers to facilitate an update of the endpoint ontology model to identify a future attack.

11. The storage disk or storage device of claim 10 , wherein the endpoint rules and the endpoint ontology model are stored in a trusted execution environment of the endpoint.

12. The storage disk or storage device of claim 10 , wherein the instructions, when executed, cause the endpoint to compare the process behaviors to an endpoint behavioral profile, the endpoint behavioral profile to include at least one of: one or more setup parameters, one or more configurations, or one or more expected behaviors.

13. The storage disk or storage device of claim 10 , wherein the endpoint ontology model includes an ontology of a compromised endpoint.

14. The storage disk or storage device of claim 13 , wherein the instructions cause the endpoint to determine the correlation fit by attempting to correlate the process behaviors of the endpoint with the ontology of the compromised endpoint.

15. An endpoint for detecting threats in a computer network, the endpoint comprising:

one or more processors; and

memory including instructions that, when executed, cause the one or more processors to:

extract first events from process behaviors performed by the endpoint using endpoint rules from one or more servers, at least one of the first events corresponding to a call to an operating system of the endpoint;

generate a first event sequence by arranging two or more of the first events into the first event sequence;

generate a third event sequence to determine a correlation fit by attempting to correlate the first event sequence to stored second event sequences of an endpoint ontology model from the one or more servers by applying a hidden Markov model to the first event sequence and the second event sequences of the endpoint ontology model, the second event sequences corresponding to known attack patterns, the third event sequence including second events, one or more of the second events being different from one or more of the first events;

generate a security alert when the correlation fit satisfies a threshold; and

transmit security event data associated with the security alert to the one or more servers to facilitate an update of the endpoint ontology model to detect suspicious behavior patterns at one or more of a plurality of endpoints including the endpoint.

16. The endpoint of claim 15 , wherein the instructions, when executed, cause the endpoint to compare the process behaviors to an endpoint behavioral profile, the endpoint behavioral profile to include at least one of: one or more setup parameters, one or more configurations, or one or more expected behaviors.

17. The endpoint of claim 15 , wherein the endpoint rules and the endpoint ontology model are accessible within a trusted execution environment.

18. The endpoint of claim 15 , wherein the endpoint ontology model is of a compromised endpoint.

19. A method of detecting threats in a computer network, the method comprising:

extracting first events from process behaviors performed by an endpoint using endpoint rules from one or more servers, at least one of the first events corresponding to a call to an operating system of the endpoint;

generating a first event sequence by arranging ones of the first events into the first event sequence;

generating a third event sequence to determine a correlation fit by attempting to correlate the first event sequence to stored second event sequences of an endpoint ontology model from the one or more servers by applying a hidden Markov model to the first event sequence and the second event sequences of the endpoint ontology model, the second event sequences corresponding to known attack patterns, the third event sequence including second events, one or more of the second events being different from one or more of the first events; and

when the correlation fit satisfies a threshold, transmitting security event data to the one or more servers to facilitate an update of the endpoint ontology model to identify a future attack at one or more of a plurality of endpoints including the endpoint.

20. The method of claim 19 , wherein the endpoint ontology model is of a compromised endpoint.

Assignments (21)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
TERMINATION AND RELEASE OF SECOND LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 056990, FRAME 0960 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0430 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
TERMINATION AND RELEASE OF FIRST LIEN SECURITY INTEREST IN CERTAIN PATENTS RECORDED AT REEL 057453, FRAME 0053 Recorded Aug 15, 2024
From: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
To: MUSARUBRA US LLC
Reel/Frame 068655/0413 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 1, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060561/0466 →
CORRECTIVE ASSIGNMENT TO CORRECT THE PROPERTY NUMBERS PREVIOUSLY RECORDED AT REEL: 057315 FRAME: 0001. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Apr 11, 2022
From: MCAFEE, LLC
To: MUSARUBRA US LLC
Reel/Frame 060878/0126 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057453/0053 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 27, 2021
From: MUSARUBRA US LLC; SKYHIGH NETWORKS, LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 056990/0960 →
RELEASE OF SECURITY INTEREST Recorded Jul 26, 2021
From: MORGAN STANLEY SENIOR FUNDING, INC.
To: MCAFEE, LLC; SKYHIGH NETWORKS, LLC
Reel/Frame 057620/0102 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 11, 2015
From: AVIDAN, YANIV; NAYSHTUT, ALEX; MUTTIK, IGOR; BEN-SHALOM, OMER
To: MCAFEE, INC.
Reel/Frame 037275/0936 →
Cited By (7)
US 12,189,791 US 12,289,332 US 12,585,657 US 12,585,772 US 12,587,546 US 12,659,330 US 12,694,146